Gerten Greenhouse & Garden Center, Inc.

Gerten Greenhouse & Garden Center, Inc.

The Maine Office of the Attorney General disclosed a data breach targeting Gerten Greenhouse & Garden Center, Inc., which transpired between May 14, 2022, and July 21, 2022, due to external hacking. The incident compromised payment card information of 2,944 customers, exposing sensitive details such as names, email addresses, card numbers, expiration dates, and security codes. At least one Maine resident was confirmed among the affected individuals. The breach posed significant risks, including potential fraudulent transactions, identity theft, and financial losses for customers. The exposure of full payment card data—a high-value target for cybercriminals—heightens the severity, as such information can be exploited for unauthorized purchases or sold on dark web marketplaces. The company’s failure to prevent the intrusion underscores vulnerabilities in its cybersecurity defenses, particularly in safeguarding customer financial data from external threats. The breach’s prolonged detection window (over two months) further exacerbates concerns about the organization’s incident response capabilities and the potential for prolonged exploitation of the compromised systems.

Source: https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/7368e3a3-2abd-49b4-afaa-34bab3385889.shtml

TPRM report: https://www.rankiteo.com/company/gertens

"id": "ger020090625",
"linkid": "gertens",
"type": "Cyber Attack",
"date": "5/2022",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 2944,
                        'industry': 'Retail (Garden Center)',
                        'name': 'Gerten Greenhouse & Garden Center, Inc.',
                        'type': 'Business'}],
 'attack_vector': 'External Hacking',
 'data_breach': {'data_exfiltration': 'Likely (payment card details exposed)',
                 'number_of_records_exposed': 2944,
                 'personally_identifiable_information': ['names',
                                                         'email addresses',
                                                         'payment card numbers',
                                                         'expiration dates',
                                                         'security codes'],
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['personally identifiable '
                                              'information (PII)',
                                              'payment card information']},
 'date_publicly_disclosed': '2022-09-14',
 'description': 'The Maine Office of the Attorney General reported a data '
                'breach involving Gerten Greenhouse & Garden Center, Inc. The '
                'breach occurred between May 14, 2022, and July 21, 2022, due '
                'to external hacking, potentially affecting 2,944 customers '
                'with exposure of payment card information including names, '
                'email addresses, card numbers, expiration dates, and security '
                'codes. One Maine resident was specifically identified as '
                'affected.',
 'impact': {'data_compromised': ['names',
                                 'email addresses',
                                 'payment card numbers',
                                 'expiration dates',
                                 'security codes'],
            'identity_theft_risk': 'High (payment card details exposed)',
            'payment_information_risk': 'High (full card details including '
                                        'security codes exposed)'},
 'references': [{'date_accessed': '2022-09-14',
                 'source': 'Maine Office of the Attorney General'}],
 'regulatory_compliance': {'regulatory_notifications': 'Maine Office of the '
                                                       'Attorney General'},
 'response': {'communication_strategy': 'Public disclosure via Maine Office of '
                                        'the Attorney General'},
 'title': 'Data Breach at Gerten Greenhouse & Garden Center, Inc.',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.